Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
The Golden Chickens malware-as-a-service (MaaS) group, tracked as TAG-195, has resurfaced with four new malware families, indicating continued development and a shift towards a more flexible, modular approach to evade detection. This evolution is driven by a financially motivated operator, TAG-127, who utilizes these tools in conjunction with other cybercrime groups like Cobalt Group and FIN6.
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem, identified as TAG-195, have resurfaced with four new malware families – TinyEgg, ChonkyChicken (including a modular variant), and ChromEggscalator – signaling ongoing development and a strategic shift in their operational methodology. Recorded Future's Insikt Group notes this transition represents an architectural evolution, driven by a financially motivated operator, TAG-127, who leverages these tools in collaboration with groups like Cobalt Group and FIN6. The group’s tools have been previously linked to TAG-127 as an operator and customer.
TinyEgg is a lightweight initial-access backdoor providing host profiling and interactive shell access, while ChonkyChicken is a fully featured implant that expands on TinyEgg with browser credential theft, live browser session control using Chrome DevTools Protocol (CDP), credential-backed remote execution, network reconnaissance, and sustained surveillance. The modular version of ChonkyChicken introduces a controller-and-plugin architecture, allowing the controller to request and load 14 discrete capability modules on demand, enhancing defense evasion. ChromEggscalator is a successor to TerraStealerV2 and a modified version of a publicly available Chrome encryption-bypass tool.
Attack chains utilize ClickFix lures to execute OCX payloads downloaded from attacker-controlled staging infrastructure, resulting in the installation of TinyEgg. The malware’s initial function is limited to initial access and profiling, with post-exploitation capabilities delivered through ChonkyChicken. TinyEgg is designed to terminate execution if sandbox and automated analysis environments are detected. The malware establishes connections with a C2 server using WebSockets to facilitate an interactive command shell, run operator-supplied input to the active shell session commands, send the output back to the controller, and stage OCX payloads.
The modular version of ChonkyChicken supports 14 different components that are fetched from the C2 infrastructure as needed, enabling selective delivery of specific functionality. These modules include process management, screen capture and monitor enumeration, file manipulation, command execution, network reconnaissance, domain-based reconnaissance, clipboard capture, keylogging, audio capture, idle time check, HTTP/S request via host, browser theft via ChromEggscalator, and persistence management. A module named "wtrack" is also included, whose purpose remains unknown, suggesting an active capability under development.
